Usable with caveats: it is a small, clearly licensed and organization-backed package with a matching repository and release notes, but recent maintenance activity is limited and the project has little public adoption or security documentation.
65%
Total Score
67
100
83
83
Only one registry account has publish access, which creates some publishing continuity risk. That concern is partly offset by the repository being owned by the matching diablomedia organization.
The project has existed since October 2018 with 10 releases, but it recorded no releases in the last 12 months, indicating a slow or paused release cadence.
There were no commits and no active maintainers in the last three months, despite the recent push metadata, so current development activity is not demonstrated.
The repository has zero stars and forks and only three watchers, indicating limited independent adoption. Popularity is supporting evidence rather than a decisive health measure, so this is a modest concern.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ergebnis/php-cs-fixer-config Version ^6.15.0 | — | — |
erickskrauch/php-cs-fixer-custom-fixers Version ~1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.